Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f9p3-h6cg-2cjr

Опубликовано: 03 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.8

Описание

Improper neutralization of formula elements in yii-helpers

Formula Injection/CSV Injection due to Improper Neutralization of Formula Elements in CSV File in GitHub repository luyadev/yii-helpers prior to 1.2.1. Successful exploitation can lead to impacts such as client-sided command injection, code execution, or remote ex-filtration of contained confidential data.

Пакеты

Наименование

luyadev/yii-helpers

composer
Затронутые версииВерсия исправления

< 1.2.1

1.2.1

EPSS

Процентиль: 60%
0.00396
Низкий

7.8 High

CVSS3

Дефекты

CWE-1236

Связанные уязвимости

CVSS3: 7.8
nvd
почти 4 года назад

Formula Injection/CSV Injection due to Improper Neutralization of Formula Elements in CSV File in GitHub repository luyadev/yii-helpers prior to 1.2.1. Successful exploitation can lead to impacts such as client-sided command injection, code execution, or remote ex-filtration of contained confidential data.

EPSS

Процентиль: 60%
0.00396
Низкий

7.8 High

CVSS3

Дефекты

CWE-1236